• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Encoded PowerShell Net Commands

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Barsha Sketh@Barshasketh
    •updated Sep 17, 2025•4•0•129

    Detects PowerShell commands using encoded command-line arguments to execute 'net user', 'net group', or 'net share' commands. This technique is often used by adversaries to obfuscate their actions and evade detection.

    Microsoft Sentinel (KQL)

    Tags

    T1027.010 - Command ObfuscationS0039 - NetTA0005 - Defense EvasionT1087.002 - Domain AccountT1136.002 - Domain AccountTA0003 - PersistenceTA0004 - Privilege EscalationT1087 - Account DiscoveryT1098.007 - Additional Local or Domain GroupsT1136 - Create AccountCommand ExecutionScript ExecutionPowershell Script ExecutionWindowsWindows Defender Atpkql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?